High · CVSS 7.5
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data.
Published May 12, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
Published May 12, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
Published May 12, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.
Published May 13, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.
Published May 13, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.
Published May 13, 2022 · Updated Apr 16, 2025
High · CVSS 8.2
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
Published May 13, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.4
The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.
Published May 16, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.
Published May 16, 2022 · Updated Apr 16, 2025
Critical · CVSS 10
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
Published May 16, 2022 · Updated Apr 16, 2025
Medium · CVSS 6.1
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.
Published May 16, 2022 · Updated Apr 16, 2025
Medium · CVSS 6.1
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
Published May 16, 2022 · Updated Apr 16, 2025
Medium · CVSS 5.6
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
Published May 16, 2022 · Updated Apr 16, 2025
Low · CVSS 3.3
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
Published May 18, 2022 · Updated Apr 16, 2025
Low · CVSS 3.3
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
Published May 18, 2022 · Updated Apr 16, 2025
High · CVSS 7.8
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
Published May 18, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.1
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conneciton, firmware using AVAPI module without enabling DTLS mechanism, and firmware using P2PTunnel or RDT module) do not sufficiently protect data transferred between the local device and ThroughTek servers. This can allow an attacker to access sensitive information, such as camera feeds.
Published May 19, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.4
Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).
Published May 23, 2022 · Updated Apr 16, 2025
Medium · CVSS 5.5
Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.
Published May 23, 2022 · Updated Apr 16, 2025
Medium · CVSS 6.5
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system.
Published May 24, 2022 · Updated Apr 16, 2025
High · CVSS 8.2
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.
Published May 24, 2022 · Updated Apr 16, 2025
Low · CVSS 3.7
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to remotely read LDAP system credentials.
Published May 25, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.3
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
Published May 25, 2022 · Updated Apr 16, 2025
High · CVSS 8.2
The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
Published May 25, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.
Published May 26, 2022 · Updated Apr 16, 2025
High · CVSS 8.8
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Published May 12, 2022 · Updated Apr 15, 2025
Medium · CVSS 5
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.
Published May 24, 2022 · Updated Apr 15, 2025
Low · CVSS 3.7
A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings.
Published May 24, 2022 · Updated Apr 15, 2025
Low · CVSS 3.5
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.
Published May 26, 2022 · Updated Apr 15, 2025
Low · CVSS 3.5
A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function of the file admin/manage-ticket.php. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. It is possible to launch the attack remotely.
Published May 26, 2022 · Updated Apr 15, 2025
High · CVSS 7.8
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the user to upload a crafted file to an affected system.
Published May 5, 2021 · Updated Apr 10, 2025
High · CVSS 8.6
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
Published May 5, 2021 · Updated Apr 10, 2025
Medium · CVSS 4.6
Microsoft SharePoint Server Spoofing Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
High · CVSS 7.6
Microsoft SharePoint Server Spoofing Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
High · CVSS 7.1
Microsoft SharePoint Server Spoofing Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
High · CVSS 7.8
Microsoft Exchange Server Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft SharePoint Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
Medium · CVSS 5.3
Microsoft SharePoint Server Information Disclosure Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
Medium · CVSS 6.5
Microsoft Exchange Server Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
Medium · CVSS 6.5
Microsoft Exchange Server Spoofing Vulnerability
Published May 11, 2021 · Updated Feb 28, 2025
Unknown · CVSS Not scored
An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
Published May 26, 2021 · Updated Feb 28, 2025
Medium · CVSS 6.1
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966.
Published May 12, 2023 · Updated Feb 13, 2025
Critical · CVSS 9.1
Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Spring Boot versions 1.1.0 before 2.1.3 and versions 2.1.4 before 2.1.5 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an attacker to send authenticated re-installation events to an app.
Published May 9, 2021 · Updated Feb 12, 2025
High · CVSS 7.8
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
Published May 8, 2023 · Updated Jan 29, 2025
High · CVSS 8.8
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
Published May 8, 2023 · Updated Jan 29, 2025
Medium · CVSS 5.4
Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file.
Published May 9, 2023 · Updated Jan 29, 2025
High · CVSS 7.2
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
Published May 8, 2023 · Updated Jan 29, 2025
High · CVSS 7.8
An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file.
Published May 9, 2023 · Updated Jan 29, 2025
Critical · CVSS 9.8
Insufficient input validation of mailbox data in the
SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially
leading to a loss of integrity and privilege escalation.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.1
Insufficient address validation, may allow an
attacker with a compromised ABL and UApp to corrupt sensitive memory locations
potentially resulting in a loss of integrity or availability.
Published May 9, 2023 · Updated Jan 28, 2025